๐ฉ๐ช
ghostwarriors
2026-09-01 05:50:35
(9 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 05:33:13
(9 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-21 08:45:59
(1 week ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /xmlrpc.php | ua: WordPress.com; https://wordpress.com (+1 more)
show less
Hacking
Web App Attack
๐ง๐ช
madeit
2026-08-19 02:55:57
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 02:39:01
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 22:38:46.298827 2026] [security2:error] [pid 23899:tid 23899] [client 202.137.158.56:61113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.137.158.56 (+1 hits since last alert)|clipper1970.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "clipper1970.com"] [uri "/xmlrpc.php"] [unique_id "aoUXNvgDhloT4XtgIMQ-KAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-18 08:12:40
(2 weeks ago)
202.137.158.56 - - [18/Aug/2026:04:11:01 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5038 "-" "WordPress. ...
show more
202.137.158.56 - - [18/Aug/2026:04:11:01 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5038 "-" "WordPress.com; https://wordpress.com"
202.137.158.56 - - [18/Aug/2026:04:11:33 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5054 "-" "WordPress.com; https://wordpress.com"
202.137.158.56 - - [18/Aug/2026:04:11:43 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5054 "-" "WordPress.com; https://wordpress.com"
202.137.158.56 - - [18/Aug/2026:04:11:54 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5054 "-" "WordPress.com; https://wordpress.com"
202.137.158.56 - - [18/Aug/2026:04:12:38 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5038 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-08-18 05:06:33
(2 weeks ago)
WordPress login brute-force | req: /xmlrpc.php | UA: Jetpack/13.0; WordPress/6.3; http://site3205729 ...
show more
WordPress login brute-force | req: /xmlrpc.php | UA: Jetpack/13.0; WordPress/6.3; http://site32057293.com
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:22:49
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:22:32.319242 2026] [security2:error] [pid 8347:tid 8347] [client 202.137.158.56:63694] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.137.158.56 (+1 hits since last alert)|reyadecostarica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "reyadecostarica.com"] [uri "/xmlrpc.php"] [unique_id "aoJ-eBqBNUJUPXK_H9YvgAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 09:53:48
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 05:53:34.145013 2026] [security2:error] [pid 2598708:tid 2598708] [client 202.137.158.56:62511] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.137.158.56 (+1 hits since last alert)|rocksolidhomebuilders.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rocksolidhomebuilders.com"] [uri "/xmlrpc.php"] [unique_id "anxCnuQMWv9lVU1jhhTULAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 09:10:10
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 05:09:53.534474 2026] [security2:error] [pid 3921925:tid 3921925] [client 202.137.158.56:57489] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.137.158.56 (+1 hits since last alert)|wokedreamer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wokedreamer.com"] [uri "/xmlrpc.php"] [unique_id "anw4YZkDAX7ZeVTtGmYDrAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 04:20:53
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 00:20:43.286779 2026] [security2:error] [pid 915780:tid 915780] [client 202.137.158.56:61648] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.137.158.56 (+1 hits since last alert)|uccryakima.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "uccryakima.org"] [uri "/xmlrpc.php"] [unique_id "anv0m4ZFNUCllzamnpKOKAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-12 03:38:09
(2 weeks ago)
[WedAug1205:38:01.1731632026][security2:error][pid3062824:tid3062968][client202.137.158.56:0]ModSecu ...
show more
[WedAug1205:38:01.1731632026][security2:error][pid3062824:tid3062968][client202.137.158.56:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"468\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"benvenutialfood.biz\"][uri\"/xmlrpc.php\"][unique_id\"anvqmZUQpMFGQc-UMKsXSQAAANE\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-08-11 04:56:32
(3 weeks ago)
WordPress XML-RPC brute-force (repeated authentication attempts via xmlrpc.php) | req: /xmlrpc.php | ...
show more
WordPress XML-RPC brute-force (repeated authentication attempts via xmlrpc.php) | req: /xmlrpc.php | UA: WordPress.com; https://wordpress.com
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 02:39:51
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 202.137.158.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 22:39:41.738747 2026] [security2:error] [pid 3810530:tid 3810551] [client 202.137.158.56:54610] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.137.158.56 (+1 hits since last alert)|dasperformance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dasperformance.com"] [uri "/xmlrpc.php"] [unique_id "anqLbUKdvPkXRKUx8McyuAAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
hostseries
2025-01-20 08:42:05
(1 year ago)
Trigger: LF_DISTATTACK
Brute-Force